Compliance · Sep 1, 2026 · 4 min read

Bot detection and compliance: GDPR, the EU AI Act and accessibility

Where bot detection meets GDPR Article 22, the EU AI Act, and accessibility law. What each regime asks for, and the questions to put to any vendor, Prosopo included.

Bot detection and compliance: GDPR, the EU AI Act and accessibility

Three regimes touch bot detection and none of them was written with bot detection in mind. That leaves a set of questions most organisations have not asked of their vendor, and most vendors have not made easy to answer.

Prosopo has a clear interest in this area: the capability it leads on, a readable reason attached to every block, is directly relevant to what these regimes ask for. The pages below set out the requirements and the questions to put to any vendor. None of it is legal advice.

The three regimes

GDPR Article 22 restricts decisions based solely on automated processing that produce legal or similarly significant effects, and requires meaningful information about the logic involved. A blocked purchase or a rejected registration is where this becomes material.

The EU AI Act regulates by risk tier. Most bot detection is not high-risk, and the parts that matter are Article 50 transparency where a system interacts with people, and Article 14 human oversight where bot detection forms part of something that is high-risk for another reason.

Accessibility law, including WCAG-based obligations and the European Accessibility Act, applies where a challenge stands between a person and a service. An image CAPTCHA on a checkout is the clearest case, and it overlaps with Article 22: a challenge a person cannot complete functions as a refusal for that person.

What they have in common

All three converge on one requirement, expressed three different ways: a human has to be able to understand an individual automated decision and act on it.

That is a hard requirement to meet if your platform returns a risk score. Not because a score is dishonest, but because nobody, including your own security team, can say what caused it. Forrester's Q2 2026 Wave marked CHEQ down for numeric reason codes that are difficult to interpret and Google reCAPTCHA Enterprise for lack of detail and limited drill-down. Those were written as usability findings. They read as compliance findings.

The five questions

Take these into every vendor conversation, ours included.

  1. Show me a blocked request from last week and tell me exactly what caused it.
  2. What does a support agent see, and how do they get from a customer complaint to that record?
  3. Can a human overturn a specific verdict, and is the override recorded?
  4. Can I export the decision records to my own systems?
  5. When the detection model changes, will I know, and will past decisions still be explainable?

Prosopo's position

Every block returns a reason. Every response carries an X-Prosopo-Request-Id correlation header. Blocks from rules your team wrote are attributable to a documented human policy rather than a model output. Events export to Datadog, Splunk, Elastic or Sentinel. Prosopo scales horizontally across points of presence in the US, LATAM, APAC and the EU, and data processing can be restricted entirely to the EU on our Enterprise plan. A dedicated database can be arranged for an Enterprise customer, so their visitors' data is never held alongside another site's and no cross-customer profiling is possible. That is worth asking about if your own users are the reason you are reading this page, rather than a regulator.

What it costs you is less than it sounds. A ringfenced customer does not contribute to or draw on cross-site behavioural modelling, but most of what that catches is catchable inside a single site's own data: a residential-proxy operation gives itself away on repeat behaviour against one target, without needing to have been seen somewhere else first. Ask us during an evaluation rather than expecting a switch in the portal.

ISO 27001 certification is in progress, with SOC 2 Type 1 on the roadmap behind it. A published model card, a WCAG conformance statement and a VPAT are planned alongside them. If your procurement needs a completed attestation by a particular date, tell us the date and we will tell you whether we can meet it.

Need to document how your bot vendor makes decisions?

Tell us what you run and what your DPO is asking for. We will show you what the verdict output contains so you can judge it against your own assessment.

Tell us about your bot problem

We'll get back to you straight away

By submitting this form, you agree to our Privacy Policy and Terms of Service

Frequently Asked Questions

Is bot detection regulated?

Not as a category. Bot detection is caught by general regimes rather than a specific one. GDPR applies because you are processing personal data to make a decision about a person. The EU AI Act applies where the system meets its definition of an AI system and the deployment falls into a regulated risk tier. Accessibility law applies where a challenge stands between a person and a service they are entitled to use.

What is the single question a DPO should ask a bot vendor?

Show me a request you blocked last week and tell me exactly what caused it. Everything else follows from whether the vendor can answer that. If the answer is a score, the meaningful-information and human-oversight requirements become very hard to satisfy, because your own team cannot interpret the output either.

Does Prosopo hold SOC 2 or ISO 27001?

ISO 27001 certification is in progress, with SOC 2 on the roadmap behind it. If your procurement has a fixed date by which an attestation must be complete, share it early and we will confirm whether we can meet it.